> For the complete documentation index, see [llms.txt](https://docs.caf.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.caf.io/caf-docs/user-guide/organizations.md).

# Organizations

Manage members, access, and security for your organization in Organizations.

**Organizations** is the Certta admin console for identity and access management. Super Admins use it to configure the organization profile, manage people (members, administrators, roles, and groups), and set up security features such as SSO and SCIM provisioning.

Each organization is accessed at its own subdomain, for example `https://certta.sso.caf.io`. **Members** sign in at that URL with **Sign in with SSO** when SSO is enabled. **Super Admins** open the admin console at `https://certta.sso.caf.io/admin-login` using email and password.

***

## Access requirements

| Requirement                | Description                                                                                               |
| -------------------------- | --------------------------------------------------------------------------------------------------------- |
| **Super Admin**            | Full access to all areas described below.                                                                 |
| **Member**                 | Can sign in and use linked Certta products according to group assignments. Cannot open the admin console. |
| **Organization subdomain** | The hostname alias identifies your tenant (for example, `certta` in `https://certta.sso.caf.io`).         |

***

## Navigation overview

The admin sidebar includes four main areas:

| Area             | Purpose                                                                                  |
| ---------------- | ---------------------------------------------------------------------------------------- |
| **Dashboard**    | Overview of members, groups, linked accounts, and roles, plus shortcuts to SSO and SCIM. |
| **Organization** | Organization status, login URL, identifier, and linked Certta accounts.                  |
| **People**       | Members, administrators, roles, and groups.                                              |
| **Security**     | SSO, attribute mapping, group assignment rules, and SCIM tokens.                         |

***

## Dashboard

The dashboard shows organization-wide counts and the status of SSO and SCIM provisioning.

<div data-with-frame="true"><img src="https://737907756-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FI4kncOam5KtDqeGMEiQu%2Fuploads%2Fgit-blob-9d3d34c5db700bc4dd98aab1e666eb391cf5ccd6%2Fdashboard.jpg?alt=media" alt="Organizations - Dashboard"></div>

| Stat                | Description                                        |
| ------------------- | -------------------------------------------------- |
| **Members**         | Total members in the organization.                 |
| **Groups**          | Groups used to bundle role and tenant assignments. |
| **Linked accounts** | Certta products linked to this organization.       |
| **Roles**           | Custom roles defined for fine-grained permissions. |

Use the SSO and SCIM cards to jump directly to the corresponding **Security** tabs.

***

## Organization

Configure organization-level settings: active status, display name, login URL, organization ID, and linked accounts.

<div data-with-frame="true"><img src="https://737907756-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FI4kncOam5KtDqeGMEiQu%2Fuploads%2Fgit-blob-f61553b04b18d09698bc9a0735ce4752bd7052d1%2Forganization.jpg?alt=media" alt="Organizations - Organization settings"></div>

| Field                   | Description                                                        |
| ----------------------- | ------------------------------------------------------------------ |
| **Organization active** | When disabled, new logins are blocked; existing data is preserved. |
| **Login URL**           | URL members use to sign in (subdomain-based).                      |
| **Organization ID**     | Internal identifier for APIs and support.                          |
| **Linked accounts**     | Certta products connected to this organization.                    |

***

## People

The **People** screen has four tabs: **Members**, **Administrators**, **Roles**, and **Groups**.

### Members

View and manage organization members. Search and filter by status, and deactivate accounts.

<div data-with-frame="true"><img src="https://737907756-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FI4kncOam5KtDqeGMEiQu%2Fuploads%2Fgit-blob-14ff7096136bbb7d9e6c9ca4c2f9c38acece0617%2Fpeople-members.jpg?alt=media" alt="Organizations - Members"></div>

### Administrators

Super Admins who can manage the organization. View the list of administrators with access to the admin console.

<div data-with-frame="true"><img src="https://737907756-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FI4kncOam5KtDqeGMEiQu%2Fuploads%2Fgit-blob-316eba4e3e7f624939d4bf50255ba7d063581134%2Fpeople-admins.jpg?alt=media" alt="Organizations - Administrators"></div>

### Roles

Define named sets of **scopes** (permissions). Roles are attached to groups; members inherit access through group membership.

<div data-with-frame="true"><img src="https://737907756-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FI4kncOam5KtDqeGMEiQu%2Fuploads%2Fgit-blob-62635a680c590854201e07c6d17bb1d094421711%2Fpeople-roles.jpg?alt=media" alt="Organizations - Roles"></div>

| Column          | Description                                                            |
| --------------- | ---------------------------------------------------------------------- |
| **Role**        | Display name of the custom role.                                       |
| **Description** | Optional summary of the role purpose.                                  |
| **Permissions** | Count of scopes assigned to the role.                                  |
| **Groups**      | Number of groups that reference this role in their access assignments. |

#### Create a role

1. Open **People** → **Roles**.
2. Select **Create role**.
3. Enter a **Name** and optional **Description**.
4. Under **Permissions**, select one or more scopes (use the filter to search by identifier).
5. Select **Save role**.

<div data-with-frame="true"><img src="https://737907756-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FI4kncOam5KtDqeGMEiQu%2Fuploads%2Fgit-blob-935228cc2d334d035968d2dedc3d4f89f4dc41ae%2Fpeople-create-role.jpg?alt=media" alt="Organizations - Create role"></div>

{% hint style="info" %}
Roles are not assigned to members directly. Attach a role to a **group** under **Accesses** so every member of that group inherits the role on the selected linked accounts.
{% endhint %}

### Groups

Bundle **role + tenant** assignments and attach members. Groups are the primary unit for access control across linked Certta products.

<div data-with-frame="true"><img src="https://737907756-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FI4kncOam5KtDqeGMEiQu%2Fuploads%2Fgit-blob-32e743a44f5beb4e9234064bddc6248e39cebbc4%2Fpeople-groups.jpg?alt=media" alt="Organizations - Groups"></div>

| Column          | Description                                                           |
| --------------- | --------------------------------------------------------------------- |
| **Name**        | Group display name.                                                   |
| **Description** | Optional summary of the group's purpose.                              |
| **Members**     | Count of members attached to the group.                               |
| **Assignments** | Count of role + linked-account access rules configured for the group. |

#### Create a group

1. Open **People** → **Groups**.
2. Select **Create group**.
3. Enter a **Group name** and optional **Description**.
4. Select **Create Group** — you are redirected to the group detail page.

<div data-with-frame="true"><img src="https://737907756-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FI4kncOam5KtDqeGMEiQu%2Fuploads%2Fgit-blob-9cc90fb7857dce3664b7500c12996444495a0b36%2Fpeople-create-group.jpg?alt=media" alt="Organizations - Create group"></div>

#### Group detail — Members and Accesses

Each group has two tabs:

| Tab          | Purpose                                                                     |
| ------------ | --------------------------------------------------------------------------- |
| **Members**  | View and add organization members to the group.                             |
| **Accesses** | Assign **roles** to **linked accounts** (all accounts or specific tenants). |

<div data-with-frame="true"><img src="https://737907756-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FI4kncOam5KtDqeGMEiQu%2Fuploads%2Fgit-blob-7ea87e82c544ba7945f7f93b3dd009eca029a70e%2Fpeople-group-detail.jpg?alt=media" alt="Organizations - Group detail members"></div>

Open the **Accesses** tab to manage which roles the group grants and on which linked accounts:

<div data-with-frame="true"><img src="https://737907756-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FI4kncOam5KtDqeGMEiQu%2Fuploads%2Fgit-blob-9b1570f0ca7fb61bcd5fb596ff5043fdffb49c11%2Fpeople-group-access.jpg?alt=media" alt="Organizations - Group accesses"></div>

Select **Add accesses** to attach a role:

1. Choose a **Role** from the list of roles defined in **People** → **Roles**.
2. Under **Where to apply**, pick **All accounts** or **Specific accounts**.
3. For specific accounts, select one or more linked accounts from the list.
4. Select **Add accesses**.

<div data-with-frame="true"><img src="https://737907756-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FI4kncOam5KtDqeGMEiQu%2Fuploads%2Fgit-blob-5760f5899fec662cfa1453a418734f327895785b%2Fpeople-group-add-access.jpg?alt=media" alt="Organizations - Add group access"></div>

{% hint style="warning" %}
Create **roles** and **groups** before configuring **Security** → **Group assignment rules**. SSO rules target existing groups — they do not create groups automatically.
{% endhint %}

***

## Security

Open **Security** in the sidebar (labeled **Authentication** in the page header). Four tabs cover federation and provisioning.

### SSO

Enable SAML or OIDC, copy Service Provider values for your identity provider, and save provider configuration.

<div data-with-frame="true"><img src="https://737907756-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FI4kncOam5KtDqeGMEiQu%2Fuploads%2Fgit-blob-0c77d58efd3441d27989810a1fca73a8ea378112%2Fsecurity-sso.jpg?alt=media" alt="Organizations - SSO configuration"></div>

See the [SSO Configuration Guide](/caf-docs/user-guide/organizations/sso-configurations.md) and provider-specific guides for step-by-step setup.

### Attribute mapping

Map identity provider claims to member fields used during SSO sign-in.

<div data-with-frame="true"><img src="https://737907756-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FI4kncOam5KtDqeGMEiQu%2Fuploads%2Fgit-blob-9ae81fd46e4979aaf8649503142ddd92e0543b5a%2Fsecurity-attribute-mapping.jpg?alt=media" alt="Organizations - Attribute mapping"></div>

### Group assignment rules

Assign members to groups automatically based on IdP attributes (for example, directory groups or department).

<div data-with-frame="true"><img src="https://737907756-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FI4kncOam5KtDqeGMEiQu%2Fuploads%2Fgit-blob-bf9a41ab122120a5af5b6a40a43a5c06e0e904e9%2Fsecurity-assignment-rules.jpg?alt=media" alt="Organizations - Group assignment rules"></div>

### SCIM

Generate a bearer token and SCIM base URL for automated user provisioning from your identity provider.

<div data-with-frame="true"><img src="https://737907756-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FI4kncOam5KtDqeGMEiQu%2Fuploads%2Fgit-blob-2da17f5ca4c4fbacce838f14c8bfc0797d767e9d%2Fsecurity-scim.jpg?alt=media" alt="Organizations - SCIM provisioning"></div>

See the [SCIM Provisioning Guide](/caf-docs/user-guide/organizations/scim-provisioning.md) for setup steps, supported operations, and how SCIM interacts with SSO.

***

## Related documentation

* [SSO Configuration](/caf-docs/user-guide/organizations/sso-configurations.md)
* [SCIM Provisioning](/caf-docs/user-guide/organizations/scim-provisioning.md)
* [Microsoft Entra ID (SAML)](/caf-docs/user-guide/organizations/sso-configurations/microsoft-entra-id.md)
* [Microsoft Entra ID (OIDC)](/caf-docs/user-guide/organizations/sso-configurations/generic.md)
* [Okta (SAML / OIDC)](/caf-docs/user-guide/organizations/sso-configurations/okta.md)
* [Auth0 (SAML / OIDC)](/caf-docs/user-guide/organizations/sso-configurations/auth0.md)
* [Google Workspace (SAML)](/caf-docs/user-guide/organizations/sso-configurations/google.md)
* [Generic Provider (SAML / OIDC)](/caf-docs/user-guide/organizations/sso-configurations/generic.md)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.caf.io/caf-docs/user-guide/organizations.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
